Virus

bonjour je suis nouveau sur le forum et je voudrai qu 'une personne m ' aide a me debarasser du virus :deepscan.generic il est place dans :c \all documents and settings\all users\setup.exe
merci d'avance

7 réponses

  1. Bonjour

    Il est important d’effectuer la manip dans sa totalité et dans l’ordre :

    Télécharge (sauf si tu les as) et colle les 3 rapports dans l’ordre

    A - ad-aware version 1.06
    (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
    voir demo
    http://pageperso.aol.fr/balltrap34/adwseflash.zip

    B - spybot version 1.4
    (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
    voir demo d utilisation
    http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

    C - Ccleaner : ( nettoyeur de registre, cookies+temps+tempos+prefetch+historique+etc..)
    Télécharge ici :
    https://www.ccleaner.com/ccleaner/download
    Tutorial ici:
    https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
    et
    http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

    D – Ewido – AVG
    AVG Anti-Spyware :

    https://www.avg.com/en-ww/free-antivirus-download

    Tu l'installes.
    Lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente!

    Lance AVG Anti-Spyware
    Clique sur le bouton Analyse (de la barre d'outils)
    Puis sur l'onglets Comment réagir, clique sur Actions recommandées. Sélectionne Quarantaine.
    Reviens à l'onglet Analyse. Clique sur Analyse complète du système.
    A la fin du scan, choisis l'option " Appliquer toutes les actions " en bas.
    Clique sur "Enregistrer le rapport". Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

    Copie/colle le rapport

    E - Scan online avec BitDefender (fonctionne uniquement sous Internet Explorer en acceptant l’ activX)
    https://assiste.com/404_La_page_demandee_n_existe_pas.php
    http://www.bitdefender.fr/scan8/ie.html
    Copie/COLLE le rapport entier

    F - Hijackthis - Outil de diagnostic et réparation
    lire démo
    http://pageperso.aol.fr/balltrap34/Hijenr.gif
    http://pageperso.aol.fr/balltrap34/demohijack.htm
    Télécharge version française ici
    http://telechargement.zebulon.fr/160-patch-francais-pour-hijackthis-1991.html
    Copie/colle le rapport

    Bon courage

    A++
    0
    1. Bonsoir.Marie je n'arrive pas a avoir le bitdefender que tu me demande de telecharger.En sachant que mon anti-virus est bitdefender.merci d'avance.Francois
      0
      1. Salut,

        Télécharge HijackThis:
        hijackthis
        Installe le dans son propre dossier:
        -clic droit sur le bureau, choisis "nouveau dossier" puis installe le dedans.
        Lance le, clic sur "do a system scan and save logfile"
        Puis copie et colle le rapport ici stp
        0
        1. Logfile of HijackThis v1.99.1
          Scan saved at 23:03:21, on 05/12/2006
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.5730.0011)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
          C:\WINDOWS\Explorer.EXE
          C:\progra~1\softwin\bitdef~1\bdswitch.exe
          C:\Program Files\Softwin\BitDefender9\bdoesrv.exe
          C:\progra~1\softwin\bitdef~1\bdnagent.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\WINDOWS\system32\LVComsX.exe
          C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
          C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
          C:\Program Files\Softwin\BitDefender9\vsserv.exe
          c:\progra~1\softwin\bitdef~1\bdmcon.exe
          C:\Documents and Settings\francois\Mes documents\Nouveau dossier\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
          O2 - BHO: (no name) - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file)
          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
          O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [BDSwitchAgent] "c:\progra~1\softwin\bitdef~1\bdswitch.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [BDMCon] c:\progra~1\softwin\bitdef~1\bdmcon.exe
          O4 - HKLM\..\Run: [BDOESRV] "C:\Program Files\Softwin\BitDefender9\bdoesrv.exe"
          O4 - HKLM\..\Run: [BDNewsAgent] "c:\progra~1\softwin\bitdef~1\bdnagent.exe"
          O4 - HKLM\..\Run: [LessBuildThirdAim] C:\Documents and Settings\All Users\Application Data\RegsVcLessBuild\findpoll.exe
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - Global Startup: BTTray.lnk = ?
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
          O8 - Extra context menu item: &Search - http://ko.bar.need2find.com/KO/menusearch.html?p=KO
          O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
          O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
          O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O11 - Options group: [INTERNATIONAL] International*
          O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
          O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
          O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
          O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
          O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
          O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
          O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
          O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
          O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
          O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
          O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender9\vsserv.exe" /service (file missing)
          O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
          0
          1. Télécharge, installe puis met à jour ce logiciel(Ewido), une fois que c'est fait, fais un scan complet de ton système, supprime (delete) tout ce qu'il te trouve puis colle le rapport ici stp
            Ewido: (en Anglais reste gratuit après la période d'essai)
            Ewido
            Si tu as besoin d'aide avec Ewido(devenu AVG-antispyware) regarde ce tutoriel:
            http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html
            0
            1. ewido anti-spyware - Scan Report
              ---------------------------------------------------------

              + Created at: 00:02:15 06/12/2006

              + Scan result:

              C:\Documents and Settings\antoine\Cookies\antoine@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
              C:\Documents and Settings\sophie\Cookies\sophie@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
              C:\Documents and Settings\antoine\Cookies\antoine@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
              C:\Documents and Settings\sophie\Cookies\sophie@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
              C:\Documents and Settings\sophie\Cookies\sophie@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
              C:\Documents and Settings\antoine\Cookies\antoine@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
              C:\Documents and Settings\sophie\Cookies\sophie@bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
              C:\Documents and Settings\antoine\Cookies\antoine@fl01.ct2.comclick[2].txt -> TrackingCookie.Comclick : No action taken.
              C:\Documents and Settings\antoine\Cookies\antoine@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
              C:\Documents and Settings\sophie\Cookies\sophie@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
              C:\Documents and Settings\sophie\Cookies\sophie@as1.falkag[2].txt -> TrackingCookie.Falkag : No action taken.
              C:\Documents and Settings\antoine\Cookies\antoine@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
              C:\Documents and Settings\sophie\Cookies\sophie@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
              C:\Documents and Settings\antoine\Cookies\antoine@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : No action taken.
              C:\Documents and Settings\sophie\Cookies\sophie@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : No action taken.
              C:\Documents and Settings\antoine\Cookies\antoine@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : No action taken.
              C:\Documents and Settings\sophie\Cookies\sophie@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : No action taken.
              C:\Documents and Settings\antoine\Cookies\antoine@weborama[2].txt -> TrackingCookie.Weborama : No action taken.
              C:\Documents and Settings\francois\Cookies\francois@weborama[1].txt -> TrackingCookie.Weborama : No action taken.
              C:\Documents and Settings\sophie\Cookies\sophie@weborama[2].txt -> TrackingCookie.Weborama : No action taken.
              C:\Documents and Settings\sophie\Cookies\sophie@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : No action taken.

              ::Report end
              0
              1. Fait ce nettoyage: (à faire réguliérement)

                ¤Telecharges et installes ceci: (n'installe pas la barre d'outil Yahoo)
                CCleaner:
                Ccleaner

                dans la colonne de gauche clic sur "erreurs" coches toutes les cases, puis cliques en bas sur "chercher des erreurs" une fois finit, cliques sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs.
                Les sauvegardes que tu aura faites tu pourra les supprimer si ton ordinateur n'a plus de problémes

                ¤Relance Ccleaner, vas dans l'onglet "nettoyeur" present sur la gauche, decoches la derniere case (Avancé si elle est cochée) puis clic sur "lancer le nettoyage"

                Si tu as besoin d'aide pour Ccleaner, regarde ce tutoriel:
                http://www.tutopat.com/viewtopic.php?t=305

                Fait ce scan stp et donne nous le résultat (cache ton ip)

                https://www.sdv.fr/

                0